
Sustain
Governance and CSMS Development
We turn your security improvements into a managed system, with written policies, a named owner for every control, regular reviews and clear measures.
Our approach
- Stage 01AssessMeasure your exposure
- Stage 02DesignPlan the architecture
- Stage 03DeployInstall the technology
- Stage 04SustainMaintain security
Overview
What the service covers and why it matters
We turn your security improvements into a cyber security management system (CSMS): written policies, a named owner for every control, scheduled review meetings and a small set of measures that senior management reviews.
This allows OT security to be managed as an ongoing programme once the initial project is finished.
- Standard
- IEC 62443-2-1
- Stage
- Sustain, stage 4 of 4
- Usually follows
- Gap assessment
- Sectors
- All
At a glance
What the programme covers
- Who is responsible for OT security, and what they are authorized to decide
- A named owner for every control, documented and agreed
- How changes to controllers are requested, approved and recorded
- Which review meetings take place, how often, and what they can decide
- What is measured, and who reviews the results
- How new plants, units or vendors are brought into the programme
Why it matters
Security improvements are often lost over time, because no one owns them and nothing measures them.
A control without an owner gradually stops working. A programme without measures is difficult to justify when budgets are reviewed.
Governance is the least visible of our seven services, but it decides whether the value of the others is kept.
Scope
What this service does not include
- Not a policy pack.Generic documents change little. Your policies are written around your plant, your staff and the way decisions are already made.
- Not a training course.The programme may identify training needs, but training is not the focus of this service.
- Not a long-term dependency.The system is designed to run without us once it has been handed over.
- No shutdown.We do not change or interrupt any running system during this work.
How it works
The steps and what you receive
- Current position established, usually from a gap assessment
- Policies drafted for your plant
- Ownership agreed for each control with the people who will hold it
- Review meetings, decision rights and schedules agreed
- A small number of measures selected
- The programme handed over to your team
What you receive
- Policies and proceduresWritten for your plant, in language your engineers can follow.
- Ownership matrixA named owner for every control, agreed with each owner.
- Meetings and measuresWhich meetings take place, what they decide, what is measured and who reviews it.
Who it is for
When this service is the right choice
- An assessment has been completed but nothing has changed since
- Controls exist but no one can say who owns them
- Security work starts again from the beginning after every project
- You need to show a regulator or insurer that security is managed on an ongoing basis

